Getting started

Set up Xora yourself.
See what’s exploitable.

Sign up, connect a repository, and point Xora at your staging environment. Every confirmed finding comes back with the request, the response, and the steps to replay it.

  1. 1

    Create your account

    Start with your work email. You verify your address before anything runs.

  2. 2

    Connect a repository

    GitHub, Bitbucket, or Azure DevOps. Xora reads your source to plan its attacks.

  3. 3

    Point Xora at staging

    Add your staging URL and a test login. Testing stays isolated from production.

  4. 4

    Get proof

    Findings arrive as working exploits your team can replay, not scanner matches.

    ✗ IDOR confirmed · /api/accounts/:id
    → Generating audit-grade evidence…

Create your account

Next you set a password, or continue with Google or GitHub, and confirm your email with a code.

By creating an account you agree to the Terms of Use and Privacy Policy.

Already have an account? Log in

Teams already running Xora

  • EscrowTech
  • Savi IQ
  • paladir
  • Spout Services
  • Alcomy
  • Reisender
  • Enzo Health
Xora was able to surface exploits that should've been caught by our previous pentesters, but weren't. The landscape has changed so much, autonomous pentesting is the future.
Conrad SouthworthCTO
Escrowtech